registeredRegistered
The application owns a purpose-bound case with opaque asset identity, SHA-256 content hash, media facts, capture time, location context, lawful-basis reference, and retention deadline.
Lock an entitled model to an immutable asset identity, call the documented synchronous prediction boundary, validate geometry and confidence, require independent review, and redact derived detections on schedule.
A state is not a UI label. It determines which actor may act, what evidence exists, what may be retried, and how recovery proceeds.
registeredThe application owns a purpose-bound case with opaque asset identity, SHA-256 content hash, media facts, capture time, location context, lawful-basis reference, and retention deadline.
model_lockedAn entitled server-discovery result and one exact API model key, fingerprint, class vocabulary, and policy version are frozen for the case.
inference_requestedOne worker owns an idempotent synchronous provider-call attempt against the exact asset and model identities.
inferredA schema-valid provider response has normalized labels, confidence, bounded geometry, timing, provenance, and response hash without becoming a business decision.
review_pendingVersioned policy places the immutable result in an uncertainty, sensitive-class, or mandatory-sampling review lane.
acceptedterminalAn independent reviewer accepted the derived evidence for the declared purpose and exact policy/model/output versions.
rejectedterminalAn independent reviewer rejected the result with an attributable reason while retaining the immutable provider evidence.
redactedterminalDerived labels and geometry were removed at the retention deadline while the minimum decision, hashes, policy, and audit record remain.
Commands express intent. The aggregate validates current state and invariants, commits one new version, and emits a fact in the same transaction.
register_caseAsset stewardvision.case_registeredOne external reference and asset hash map to one case across retries.
lock_modelVision workerregisteredvision.model_lockedServer reference, model key, metadata fingerprint, and policy version identify one lock.
request_inferenceVision workermodel_lockedvision.inference_requestedOne attempt identity binds the case version, asset hash, model fingerprint, and request policy.
record_inferenceVision workerinference_requestedvision.inference_recordedProvider status and response hash close one active attempt exactly once.
submit_reviewPolicy serviceinferredvision.review_requestedThresholds, reason codes, policy version, and attempt identity create one immutable review request.
acceptIndependent reviewerreview_pendingvision.acceptedReviewer, reason, policy, attempt, and expected aggregate version identify the terminal decision.
rejectIndependent reviewerreview_pendingvision.rejectedReviewer, reason, policy, attempt, and expected aggregate version identify the terminal decision.
redactPrivacy workerinferredreview_pendingacceptedrejectedvision.redactedOne retention action removes derived detail while preserving the minimum integrity and audit record.
Keep provider responses, business identity, state, events, and side-effect delivery distinct so each can be reconciled safely.
Business purpose, external identity, lifecycle, policy, retention, and optimistic version.
caseIdexternalIdpurposestateversionpolicyVersionretentionUntilOpaque, non-media identity and integrity facts for one captured source.
assetRefsha256mediaClasswidthheightcapturedAtlawfulBasisRefExact entitled discovery evidence and immutable model selection.
serverRefapiModelKeymodelFingerprintclasseslockedAtSynchronous request lifecycle, normalized response, safe failure, timing, and provenance.
attemptIdassetHashmodelFingerprintstatusresultHashregionstimingsPolicy reasoning, attributable disposition, and derived-detail redaction evidence.
reviewIdreasonCodesreviewerdecisionredactedAtAppend-only state evidence and exactly-once-in-effect downstream notification.
eventIdaggregateVersionidempotencyKeyactoroutboxStatusNo image bytes, media URL, bearer token, credential, face, number plate, or provider-internal file path enters the reference case store.
The provider POST /predict call is synchronous; application queue, review, retry, decision, and retention states are never attributed to SkyDNN.
Every attempt binds an immutable asset hash to one discovered model fingerprint and policy version.
Confidence and geometry are evidence, not a business outcome or live safety command.
Reviewer identity is independent from the fixture inference actor and every override or rejection has a reason.
Idempotency, optimistic versions, audit, receipts, and outbox commit atomically.
Recovery changes durable truth only through the same rules as normal operation. A timeout is an unknown outcome, not evidence that nothing happened.
Current metadata fingerprint differs from the locked fingerprint.
Stop, create a new model lock and attempt, and retain the original lock for comparison.
The active attempt has no terminal response hash and transport outcome is ambiguous.
Reconcile with the approved provider boundary when possible or record a safe failed attempt before a deliberate linked retry.
Schema, bounds, topology, vocabulary, or numeric validation fails.
Quarantine derived detail, retain a safe error class, and do not send it to policy or review.
A privacy class, low confidence, unsupported label, or mandatory sample rule matches.
Require independent review and prevent automation from issuing a terminal business or safety action.
Derived output remains present after the committed policy deadline.
Redact on schedule, close or fail the review with explicit expiry, and retain minimum audit evidence.
The client lacks acknowledgement while snapshot, receipt, audit, and outbox are durable.
Reload and replay the same idempotency key without duplicating attempts, decisions, or events.
Measure state age, event health, retries, reconciliation, and sensitive-data access alongside latency and error rate.
Only explicitly indexed evidence is linked. Empty sections are not backfilled with invented endpoints or package names.
8 labs · 5 hostile scenarios/server/whoami/models/{api_model_key}/predictskydnn-aiapi-docs10 verified tests